[ LEGAL FAQ ]

    What CookieJar does — and what it doesn't.

    Last reviewed 2026-05-08

    About CookieJar

    What is CookieJar?
    CookieJar is a Consent Management Platform (CMP) — software that shows your visitors a cookie / privacy banner, records their choices, and tells your site which trackers it may load. We ship a banner script, a cookie scanner, an audit log, and admin tooling.
    What is CookieJar NOT?
    CookieJar is not a law firm and does not provide legal advice. We don't certify your site as “compliant”, we don't act as your Data Protection Officer, and we don't represent you before any regulator. We're a tool — using it correctly is necessary but not sufficient on its own.
    Do you guarantee compliance?
    No CMP can. Compliance depends on what trackers you load, how your team configures the banner, your privacy notice, your processing activities, and the laws of every jurisdiction your visitors come from. We give you the controls and the audit trail; you (ideally with counsel) make the legal calls.

    Per-regime workflows

    How does CookieJar support GDPR / ePrivacy workflows?
    We block non-essential cookies before consent, present a banner with granular per-category opt-ins (Art. 7 “freely given, specific, informed and unambiguous”), record an auditable consent receipt with timestamp + banner version, and let visitors withdraw consent as easily as they gave it via the persistent cookie-preferences link.
    How does CookieJar support CCPA / CPRA workflows?
    For California visitors we render an opt-out flow with a “Do Not Sell or Share My Personal Information” link, honour the Global Privacy Control (GPC) signal automatically, and keep a 12-month rolling consent log so you can respond to verifiable consumer requests.
    How does CookieJar support LGPD workflows?
    Brazilian visitors see a Portuguese-language banner that captures lawful-basis selection per Art. 8 of LGPD. Consent records include the basis claimed and are exportable for ANPD requests.
    What about U.S. state laws beyond California?
    Geo-detection routes Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA) and others to the appropriate banner variant. New states ship as policy updates — no code change required on your end.
    Do you handle Data Subject Access Requests (DSARs)?
    We help with the consent-record portion. Given a hashed visitor identifier, you can export every consent event we hold for that visitor as JSON or CSV. We don't process DSARs for data held in your other systems (CRM, analytics, etc.) — that's on you.

    Disclaimers & corrections

    Where can I read your full disclaimer?
    The Terms of Service set out the full liability and warranty position. In short: the service is provided “as-is”, you're responsible for configuring it correctly for your site, and nothing on this page or in the product constitutes legal advice.
    How often is this page reviewed?
    Last reviewed 2026-05-08. We review this page whenever a regime we cite materially changes (e.g. new EU guidance, new U.S. state law in force) or at least every six months.
    I think a citation on the marketing site is wrong. Who do I tell?
    Email legal@cookiej.ar with the page URL and the issue. We treat citation errors as bugs and fix them on the next deploy.

    Statutes & references

    • GDPR Art. 7 — Regulation (EU) 2016/679 — General Data Protection Regulation, Article 7: Conditions for consent.
    • GDPR Art. 15 — Regulation (EU) 2016/679, Article 15: Right of access by the data subject (the basis for DSARs).
    • ePrivacy Directive Art. 5(3) — Directive 2002/58/EC (consolidated text of 19 December 2009), Article 5(3): consent required for storing or accessing information on a user's device.
    • CCPA / CPRA — California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code § 1798.100 et seq.).
    • LGPD Art. 8 — Lei Geral de Proteção de Dados Pessoais (Lei nº 13.709/2018), Article 8 — consent requirements.
    • PIPEDA Principle 3 — Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), Principle 3 — Consent.
    • IAB TCF v2.2 — IAB Europe Transparency & Consent Framework, Policy version 2.2 (May 2023).
    • U.S. state privacy laws — Active comprehensive U.S. state privacy laws as of 2026: California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and 11 others. See IAPP State Tracker.